cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1320
Views
0
Helpful
2
Replies

Certificate and SAML auth with AnyConnect

Antonio Macia
Level 3
Level 3

Hi,

Is it possible to perform certificate authentication in ASA with AnyConnect together with SAML using Cisco DUO Access Gateway?

 

Thanks.

2 Replies 2

Hi,

Yes that should be possible. With the ASA, under the tunnel-group configuration you can specify "aaa" for the DUO authentication AND "certificate" for the certificate authentication. The ASA will need to trust and validate the certificate presented by the client computer.

 

tunnel-group RAVPN webvpn-attributes
 authentication aaa certificate

HTH

Hi,

 

I already tried that but it doesn't work. Notice that selecting any other option different from "SAML" will make ASA to ignore the SAML Server configured below and use only the AAA server defined.

It should work using the DUO's Authentication Proxy as secondary AAA server, since it is a regular RADIUS server, but it has some limitations compared with the Access Gateway.

 

Regards.